Splunk Enterprise Security

What happens to ES, it's settings, configurations when Splunk Enterprise is upgraded to a new version like 8.2.2.1 ?

SamHTexas
Builder

We have Splunk Ent. (8.0) & ES.(6.4). What is a proper procedure to upgrade to Splunk Enterprise 8.2.2.1 to retain the settings & configurations we have done to ES (Enterprise Security)? What about Security Essentials we have installed. Any directions are much appreciated. Thanks a million.

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Depends of what you have already done with your installation. Since you ask many questions which should be covered by any reasonable basic splunk training and seem to not put any effort into finding answers on your own, we can imagine that your servers are not managed the way they should be.

So, if you fiddled with "default" directories of the built-in apps, upgrade will overwrite your changes. If you kept your configurations in "local", nothing bad should happen.

And app upgrade is a different thing than core splunk software upgrade.

0 Karma
Get Updates on the Splunk Community!

Bridging the Gap: Splunk Helps Students Move from Classroom to Career

The Splunk Community is a powerful network of users, educators, and organizations working together to tackle ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...